4 ms·
> It can usually already write all over your system and perform all sorts of other attacks Not necessarily. Properly sandboxed applications like Chromium have
by trulyrandom 8y ago
> It can usually already write all over your system and perform all sorts of other attacks
Not necessarily. Properly sandboxed applications like Chromium have a seccomp filter, separate pid/user/etc namespaces and bind mounts setup to isolate themselves from the rest of the system as much as possible.
> Anyway, if a typical user's browser is compromised, they're already completely screwed
It really depends on which part of the browser is compromised. Again, Chromium has some pretty good isolation. Having one malicious website exploit a vulnerability does not necessarily mean the attacker gets access to any of the other browser data.
- pmoriarty 8y agoIf the browser as a whole has not been compromised, then internally it should be able to deal with the clipboard the same what that Wayland deals with it. For instance, only the currently focused tab should have access to the X clipboard.